CompTIA Security+ (SY0-701)Security OperationsMedium

A security analyst is investigating a persistent threat actor leveraging unknown malware. The analyst needs to understand the malware's capabilities, including its command-and-control (C2) communication patterns, without risking the production environment. Which of the following analysis techniques would be MOST appropriate for this scenario?

  1. ADynamic malware analysis (sandboxing)
  2. BStatic malware analysis
  3. CSignature-based antivirus scanning
  4. DFile integrity monitoring
Show answer & explanation

Correct answer: A. Dynamic malware analysis (sandboxing)

Dynamic malware analysis, often performed in a sandbox, allows security analysts to execute suspicious code in a controlled, isolated environment. This enables observation of its real-time behavior, including network communication, file system modifications, and process interactions, without endangering production systems.

Why the other options are wrong

  • B. Static analysis examines the code without executing it, which would not reveal C2 communication patterns.
  • C. Signature-based antivirus scanning relies on known signatures and would likely miss unknown malware.
  • D. File integrity monitoring detects unauthorized changes to files but does not analyze malware behavior or C2 communication.

Dynamic Malware Analysis (Sandboxing)

The execution of suspicious code in an isolated, controlled environment (a sandbox) to observe its runtime behavior.

  • Observes real-time malware actions.
  • Protects production systems from infection.
  • Reveals C2 communication, file changes, process activity.

Memory trick: To really SEE a virus, you need to LET it RUN in a SAFE PLAYPEN.

More Security Operations questions